Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Windows365 Connection Activity Logs. Contains connection lifecycle data for Cloud PC sessions, correlated with other datasets through ActivityId.
Table attributes
| Attribute | Value |
|---|---|
| Resource types | microsoft.intune/operations |
| Categories | Azure Monitor |
| Solutions | LogManagement |
| Basic table support | Yes |
| Auxiliary / Lake table support | Yes |
| DCR workspace transformation support | No |
| Ingestion API support | No |
| Sample Queries | - |
Columns
| Column | Type | Description |
|---|---|---|
| ActivityId | string | The activity Id for correlating with network, error, and checkpoint data. |
| _BilledSize | real | The record size in bytes |
| CallerIPAddress | string | The IP address of the caller. |
| ClientOS | string | The OS of the client that is connecting (if available). |
| CloudPCId | string | The unique identifier of the Cloud PC. |
| GatewayRegion | string | The region of the gateway for the server side user connection. |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account |
| ManagedDeviceName | string | The name of the managed device. |
| PlatformName | string | The platform name of the client application. |
| PlatformVersion | string | The version of the client platform. |
| _ResourceId | string | A unique identifier for the resource that the record is associated with |
| ResultType | string | The result type of the connection. |
| SessionHostIPAddress | string | The IP address of the session host. |
| SessionHostOSDescription | string | The OS SKU description of the machine where the user connection was orchestrated. |
| SessionHostOSVersion | string | The OS version of the session host. |
| SessionHostSxSStackVersion | string | The side-by-side (SxS) stack version of the session host. |
| SourceSystem | string | The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics |
| State | string | The state of the connection. |
| _SubscriptionId | string | A unique identifier for the subscription that the record is associated with |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | The timestamp (UTC) of the event. |
| TransportType | string | The type of transport used by the RDP connection: Shortpath, TURN, Websocket. |
| Type | string | The name of the table |
| UserPrincipalName | string | The user principal name of the user who initiated the connection. |